Architecture
← Back to Index | Previous: Introduction | Next: Prerequisites →
2.1 Split topology
Enterprise deployments use two hosts by default:
| Host role | Product | Public entry |
|---|---|---|
| DAI host | Deslicer AI + Control | https://<dai-host>/ and https://<dai-host>/control (443) |
| DAP host | Deslicer Automation Platform | Observer API / edge on https://<dap-host>/ (443); Observer UI on https://<dap-host>:8443 |
In copy-paste commands throughout this guide:
| Placeholder | Substitute with |
|---|---|
<dai-host> | Public DAI FQDN (browsers and Control) |
<dap-host> | Public DAP FQDN (Observer API on 443, Observer UI on 8443) |
| Deslicer registry hostnames | Leave as written (artifact-registry.deslicer.io, container-registry.deslicer.io, …) |
Keep Compose projects separate even if you later colocate them. That preserves the ability to move products independently.
Connection and data flow (split-host)
Human-readable overview of who talks to whom. On a split install, Deslicer AI reaches DAP only through the DAP public edge URL on 443 (not the Observer UI port 8443, and not private management 8080).
The dotted edge is the Insights-TA-only uplink when a full worker node is not deployed; it uses the same outbound 443 path as the worker.
Request / data-flow summary
| Flow | Path | Port |
|---|---|---|
| DAI UI / Control | End users → DAI Caddy on the DAI host | 443 HTTPS |
| DAP UI | Platform operators → DAP Caddy UI listener | 8443 HTTPS |
| Enrollment / worker uplink | Splunk host → DAP edge / API | 443 HTTPS |
| DAI → DAP (server-side) | DAI web → DAP public edge URL | 443 HTTPS |
| Agent Splunk tools | DAI splunk-mcp → Splunk management API | 8089 HTTPS |
| DAP plan / host ops | DAP observer-api → Splunk management API | 8089 HTTPS |
| Agent LLM (BYOK egress) | DAI litellm → your LLM provider APIs | 443 HTTPS |
Public DAP ports on the DAP hostname (same DAP host, two ports):
:443— DAP edge / API for workers, Insights TA, and DAI server-side calls:8443— DAP UI for platform operators only
Management :8080 stays private (not exposed at the perimeter). Internal-only services (DAI app-db, redis, DAP NATS/postgres, and similar) are not published publicly.
Edge routing detail (loopback)
Containers listen on loopback; Deslicer Caddy owns the public listeners:
2.2 Deslicer AI URL map
Deslicer AI does not publish the application directly on the public interface. Containers listen on loopback; Deslicer Caddy terminates TLS on port 443 and routes:
| Public URL | Upstream |
|---|---|
https://<dai-host>/ | 127.0.0.1:13000 (main application) |
https://<dai-host>/control | 127.0.0.1:13001 (Control) |
https://<dai-host>/api/control* | 127.0.0.1:13001 |
The same DAI hostname certificate covers / and /control. Replace <dai-host> with your DAI FQDN, not the DAP hostname.
2.3 DAP URL map
DAP uses Deslicer Caddy for its public edge. On the default split-host enroll path, Caddy publishes:
| Public URL | Role |
|---|---|
https://<dap-host>/ (port 443) | Observer API (data / management multiplex as configured) |
https://<dap-host>:8443 | Observer management UI |
Application containers stay on loopback; only Caddy listens on the public ports. Always use the URLs Control shows when installing if an engagement overrides the defaults. Replace <dap-host> with your DAP FQDN.
On a split topology (DAI and DAP on separate hosts), Deslicer AI Control stores the public edge URL (HTTPS on 443) for both the server-side backend probe and the tenant-facing Observer URL. Probes and dashboard calls leave the DAI host over HTTPS to that DAP hostname. Always use the Observer URL Control shows for your engagement.
2.4 Why Caddy is part of the product
Deslicer ships and configures Deslicer-supplied Caddy on each product host:
- Loopback-only application binds reduce accidental exposure of app ports
- Path routing for
/and/controlon one certificate - Certificate modes: automatic HTTPS (ACME) or customer-provided PEM
- Certificate changes can be applied without recreating the full Compose stack (proxy-only apply refreshes PEMs, regenerates the Deslicer-managed Caddyfile, and reloads Caddy)
- Extra listeners (additional Caddy hostnames/IPs) are stored on the host sidecar
/etc/deslicer/edge-proxy-extra-listeners.json. Control → Updates Nexus--updateregenerates Caddy routes and rehydrates extras from that sidecar (first run after this recovery can seed the sidecar from the live Caddyfile). Hand-edits of/etc/caddy/Caddyfileare not supported - An optional corporate load balancer in front of Caddy must still target Deslicer Caddy. Add the product host IP (and extra names the LB uses) to extra listeners and the PEM SAN — see Chapter 6 §6.9
You do not need to design your own nginx/HAProxy config for the primary install path. An optional corporate load balancer in front of Caddy is an advanced overlay; Deslicer still installs and manages Caddy on the product hosts.
If your environment cannot publish DNS FQDNs and you are considering IP-only URLs, see Chapter 6 §6.7.
2.5 Data and secrets layout (host)
Typical paths after install:
| Path | Purpose |
|---|---|
/opt/deslicer/ai | Deslicer AI Compose project and .env on the DAI host |
/opt/deslicer/dap | DAP Compose project and .env on the DAP host |
/opt/deslicer/bin | Published install and uninstall scripts (Chapter 5, Chapter 7) |
/etc/caddy/ | Caddyfile and certificate material on each product host (/etc/caddy/certs/<hostname>/ for provided PEMs) |
/etc/deslicer/edge-proxy-extra-listeners.json | Extra Caddy listener hostnames/IPs (no PEMs). --update rehydrates extras from this sidecar |
Treat install answers, age identities, and registry passwords as secrets. Do not commit them to git.
2.6 DAP install package updates
DAP host install uses an install package served by Deslicer AI Control (token-gated). That package updates independently from the Deslicer AI application image.
Operators apply updates in Control → Updates → DAP (Apply update or air-gapped Import package). There is no host environment variable to pin the install package. Control does not auto-apply packages on registry poll.
Reading version numbers
Control shows several version-like strings. They can look similar but update independently; the digest or package checksum is what “up to date” means.
| Surface | What it versions | How to read “up to date” |
|---|---|---|
| Control → Updates → Deslicer AI web | Application image on the floating channel | Installed matches Available when OCI digests match |
| Web footer "Build" | Build stamp in the running image | Informational bake stamp — not a registry lookup |
| Control → Updates → DAP backends | Per-backend running images | OCI digests on the DAP host after --update — do not treat tip-only views as Installed |
| Control → Updates → DAP registry tips | Available image tips in the registry | Availability only — not host Installed state |
| Control → Updates → DAP install package | DAP install package | Package checksum (sha256) — up to date when the applied package matches the registry tip |
DAP install package versions use a build-stamp or git-style form on purpose so they are not confused with Deslicer AI 0.x.y image versions. Applying a DAP package never changes the Deslicer AI image, and promoting a new Deslicer AI image never changes the DAP package. Control blocks Apply when the package needs a newer Deslicer AI; choosing a non-latest package requires explicit confirmation.
DAP per-backend Installed: After a successful DAP --update, Control can compare digests for each active backend. Until a DAP host has completed such an update, Installed may show Unknown (expected). An unreachable backend shows Unknown for that backend only and does not hide updates available on healthy peers.
Trust and recovery:
- Control verifies the package checksum before caching and again when serving it
- Downloads use allowlisted HTTPS hosts on the artifact registry
- Roll back restores the previous verified package in Control
- A new Deslicer AI image is still required when enroll APIs or provision schema change; routine DAP package updates do not change the Deslicer AI image
← Back to Index | Previous: Introduction | Next: Prerequisites →